pocoo Jinja2 2.10

CPE Details

pocoo Jinja2 2.10
2.10
2019-03-11
17h49 +00:00
2019-03-11
17h49 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:pocoo:jinja2:2.10:*:*:*:*:*:*:*

Informations

Vendor

pocoo

Product

jinja2

Version

2.10

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-8341 2019-02-15 06h00 +00:00 An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxing
9.8
Critique